Privacy Notice
Version: 2026-08-18
Effective date: 18 August 2026
This Privacy Notice explains how SMSFlow (Pty) Limited (“SMSFlow”, “we”, “us” or “our”) processes personal information in connection with our websites, portals, APIs, SMS and WhatsApp messaging services, inbox, campaigns, templates, integrations, billing, support, and related services (“Services”).
It is the single proposed SMSFlow Privacy Notice. It replaces the privacy text currently embedded in the combined Terms and Conditions page once approved and published.
1. Who we are and how to contact us
SMSFlow (Pty) Limited is a South African company, registration number 2024/051424/07, and forms part of the Flownamix group of companies.
Physical and domicilium address: 12 Waterford Office Park, Waterford Drive, Maroeladal, Fourways, 2191, South Africa.
Telephone: +27 (0) 10 823 5194
Website: https://www.smsflow.co.za
Privacy enquiries: [email protected]
Support: [email protected]
Information Officer: Eugene Smit, CTO, [email protected].
Deputy Information Officer: Lorette du Plooy, Group Head of Legal, [email protected].
The SMSFlow PAIA Manual is available at https://smsflow.co.za/paia/.
2. Scope
This Notice applies to:
- visitors to SMSFlow websites and documentation;
- prospective, current, and former customers, administrators, users, developers, billing contacts, and support contacts;
- people who communicate with SMSFlow directly;
- recipients and contacts whose information a customer processes through the Services;
- users of SMSFlow APIs, webhooks, integrations, campaigns, templates, inbox, and reporting features;
- job applicants and supplier or partner representatives, where relevant; and
- security, abuse, complaint, audit, and regulatory records relating to the Services.
It does not replace a customer’s own privacy notice to its recipients. Customers must explain their processing and provide a lawful contact channel.
3. Our privacy roles
The role depends on the processing activity.
3.1 SMSFlow as responsible party
SMSFlow generally determines the purpose and means of processing for its own:
- website, prospect, account, user, contract, billing, payment, and supplier administration;
- authentication, security, audit, fraud, abuse, platform-integrity, and legal-compliance records;
- support, service-quality, product analytics, and business operations;
- service announcements and SMSFlow’s own lawful marketing; and
- provider, app, connection, and platform administration necessary to operate SMSFlow.
For this processing, SMSFlow acts as the responsible party under POPIA.
3.2 SMSFlow as operator for a customer
When a customer uploads contacts, creates templates or campaigns, sends messages, manages inbox conversations, configures automations, or connects systems, the customer generally determines why and to whom communications are sent. SMSFlow processes that Customer Data on documented instructions to provide the Services and generally acts as the customer’s operator under POPIA.
The Data Processing Addendum governs operator processing. Customer recipients should ordinarily direct requests about Customer Data to the relevant customer. SMSFlow will assist and will act directly where law requires.
3.3 Providers and other responsible parties
Mobile networks, Meta/WhatsApp, payment providers, identity providers, and customer-selected integrations may process information under their own terms and privacy notices and may act as independent responsible parties for parts of their processing. SMSFlow does not control their independent processing.
4. Personal information we process
Depending on the relationship and enabled Services, we may process:
4.1 Account and business information
- names, job titles, employer, business registration and contact details;
- usernames, account identifiers, roles, permissions, authentication and access records;
- order forms, plans, seats, entitlements, support tier, and administrative settings;
- billing contacts, addresses, tax information, payment status, invoices, balances, and transaction references; and
- communications, enquiries, tickets, complaints, feedback, and training records.
4.2 Contact, consent, and suppression information
- names, mobile numbers, email addresses, custom fields, group membership, and source information;
- consent source, time, channel, category, scope, notice version, collection context, and evidence;
- opt-outs, objections, do-not-contact status, WhatsApp blocks, conversation blocks, and other suppression events; and
- eligibility, exclusion, quiet-hour, frequency, and authorisation decisions.
4.3 Messaging and channel information
- sender and recipient identifiers;
- message, template, button, interactive, reply, note, and media content;
- campaign, schedule, route, channel, source workflow, and fallback information;
- delivery, sent, read, failed, reply, quality, restriction, and provider-status events;
- conversation, assignment, team, tag, unread, priority, SLA, automation, and agent-activity records;
- WABA, business portfolio, phone-number, display-name, app, template, catalogue, and provider identifiers; and
- webhooks, event identifiers, idempotency keys, correlation and causation identifiers, and bounded diagnostic evidence.
4.4 Device, usage, and security information
- IP address, browser, device, operating system, session, cookie, referrer, and approximate location information;
- authentication events, failed logins, permission changes, API use, audit events, and security telemetry;
- service usage, performance, errors, queue and delivery diagnostics, and feature interactions; and
- suspicious activity, abuse indicators, policy decisions, incident, and investigation records.
4.5 Provider cost and customer charging information
- message category and destination pricing evidence;
- estimates, reservations, provider-cost evidence, customer price decisions, settlements, releases, adjustments, reversals, and refunds; and
- reconciliation runs, discrepancies, invoice evidence, and billing disputes.
4.6 Special personal information and children
The Services are not designed for children to contract with SMSFlow. Customers must not process children’s or special personal information through the Services unless they have a lawful basis, satisfy POPIA and sector requirements, and have an appropriate written agreement and controls with SMSFlow. WhatsApp and other providers may impose additional age, country, health, financial, or regulated-industry restrictions.
Customers must not use WhatsApp to request or share full payment-card numbers, financial-account numbers, identification-document numbers, or other prohibited sensitive identifiers.
4.7 Recruitment, suppliers, and corporate administration
For job applicants, personnel, suppliers, partners, shareholders, directors, and professional advisers, SMSFlow may process CV and application information, qualifications, work history, references, interview and assessment records, right-to-work and identity information, background information where lawful, contracts, payment and tax details, conflicts, access records, and business correspondence. SMSFlow uses this information for recruitment, workforce and supplier administration, due diligence, contracting, payment, security, governance, and legal compliance. Special personal information is processed only where authorised by law or valid consent and subject to appropriate safeguards.
5. How we collect information
We collect information:
- directly from you when you visit, register, contract, pay, configure, upload, send, receive, integrate, or request support;
- from your employer or account administrator;
- from customers who provide recipient and messaging data;
- from recipients who send messages, replies, opt-outs, complaints, or media;
- from mobile networks, Meta/WhatsApp, payment providers, identity providers, and other service providers;
- through APIs, webhooks, cookies, logs, devices, monitoring, and security tools;
- from public business records and lawfully available sources; and
- from group companies where necessary and lawful.
6. Why we process information
We process information to:
- create and administer accounts, users, permissions, subscriptions, and contracts;
- connect channels, numbers, WABAs, templates, APIs, webhooks, and integrations;
- validate, queue, route, send, receive, store, and report messages and media;
- provide contacts, groups, campaigns, templates, inbox, assignment, support, reporting, and automation;
- evidence consent, apply suppression, enforce service windows, quiet hours, frequency and content rules, and protect recipients;
- authenticate users, secure the Services, detect abuse, prevent fraud, investigate incidents, and maintain audit evidence;
- provide support, diagnose failures, communicate service information, and improve reliability and usability;
- estimate and reconcile provider costs, apply agreed pricing, administer balances, invoice, collect, refund, and resolve disputes;
- comply with law, court orders, regulatory duties, provider requirements, and lawful requests;
- establish, exercise, or defend legal rights; and
- send SMSFlow’s own marketing where lawful and allow objection or opt-out.
For applicants and suppliers, purposes also include assessing applications or capability, contacting references, entering and administering a relationship, paying valid amounts, managing access and conflicts, and retaining records required for governance or law.
POPIA permits processing on more than one basis, including consent, contract performance, legal obligation, protection of legitimate interests, and the responsible party’s legitimate interests subject to the rights of the data subject. SMSFlow does not rely on a statement that merely visiting the website constitutes consent to all processing.
7. Messaging consent and suppression
Customers are responsible for obtaining and retaining lawful, channel-appropriate consent and notices. Consent evidence should identify the person or number, source, timestamp, channel, message category or scope, notice/version, collection context, and responsible customer.
Marketing consent must not be inferred merely from a service enquiry or inbound message. An inbound WhatsApp message may permit a contextual service response within the applicable customer-service window, but does not silently remove an existing proactive or Marketing suppression.
SMSFlow records and enforces suppression evidence. The most protective applicable state takes precedence, including legal restrictions, recipient blocks, all-channel opt-out, channel-specific opt-out, category-specific opt-out, conversation blocks, and do-not-contact Marketing restrictions. Customers must propagate requests received through WhatsApp, SMS, API, import, support, or another channel according to the request’s expressed scope.
8. Automated processing
The Services may automatically validate contacts and templates, remove duplicate recipients, calculate message eligibility and estimated cost, apply consent and suppression rules, route messages, detect technical failures or suspected abuse, assign conversations under Customer-configured rules, calculate service indicators, and pause restricted activity. These controls determine whether a requested message or platform action may proceed. They are not intended to assess a recipient’s creditworthiness, employment performance, health, reliability, or eligibility for a product, service, benefit, or legal right.
If SMSFlow proposes a future feature that uses personal information to profile a data subject and make a solely automated decision producing legal consequences or affecting that data subject to a substantial degree, SMSFlow will conduct and document a POPIA section 71 assessment before enabling the feature and implement any required safeguards, including an appropriate opportunity for human review and representations.
9. Sharing and subprocessors
We may share information, limited to what is necessary, with:
- mobile networks, messaging aggregators, Meta/WhatsApp, and other channel providers;
- hosting, database, object-storage, queueing, secret-management, monitoring, security, support, email, identity, and backup providers;
- payment processors, banks, accountants, auditors, insurers, and professional advisers;
- Flownamix group companies providing authorised operational services;
- customer-selected applications and webhook destinations;
- regulators, courts, law enforcement, or authorities where required or permitted; and
- a successor in a merger, reorganisation, financing, or sale, subject to appropriate confidentiality and legal safeguards.
SMSFlow maintains a current public subprocessor register at https://smsflow.co.za/subprocessors/, identifying material production providers, purpose, primary processing location where appropriate, and applicable transfer safeguards. SMSFlow may update it as providers and architecture change.
Development emulators and MockMeta test services are not production subprocessors and must not process production Customer Data.
10. Cross-border processing
Some providers, including Meta/WhatsApp and cloud or support providers, may process information outside South Africa. SMSFlow will use an applicable POPIA section 72 transfer condition, such as an adequate legal framework, binding agreement providing an adequate level of protection, a transfer necessary for contract performance, or another lawful ground.
Where SMSFlow acts as operator, Customer authorises documented transfers necessary to provide the selected Services, subject to the DPA and subprocessor register. Consent is not treated as the sole universal transfer mechanism.
11. Security
SMSFlow uses technical and organisational safeguards appropriate to the nature and risk of the processing. Depending on the Service, these include tenant isolation, server-side authorisation, least-privilege permissions, encryption in transit and at rest where supported, secret-reference storage, bounded payloads, secure development practices, audit logging, idempotency, backups, monitoring, and incident response.
Provider credentials must not be exposed to browser clients or ordinary users. Media access should be authorised and time-limited. Customers remain responsible for their devices, credentials, users, integrations, recipient data, and secure configuration.
No security measure eliminates all risk. If SMSFlow reasonably believes personal information has been accessed or acquired by an unauthorised person, it will follow POPIA and applicable contractual notification duties, cooperate with the responsible customer where SMSFlow acts as operator, and preserve appropriate evidence.
12. Retention
SMSFlow retains personal information only for as long as required for the purpose, contract, legal obligation, dispute, security, suppression, audit, billing, or provider reconciliation need. No category is retained indefinitely by default merely because it is a log or operational record.
The approved retention schedule distinguishes:
- website enquiries and prospect data;
- account, contract, user, and support records;
- contacts, consent, and suppression evidence;
- messages, media, conversations, and delivery events;
- templates and provider-operation history;
- raw webhooks, normalised events, outbox/inbox records, failures, and dead letters;
- security and audit telemetry;
- provider-cost, ledger, invoice, tax, and reconciliation records;
- backups and disaster-recovery copies; and
- test and harness evidence.
Suppression records may be retained after ordinary messaging data is deleted where needed to prevent unwanted future contact. Provider-deleted WhatsApp templates may be retained locally as history where required for audit, billing, or dispute evidence.
Unless a longer period is required by law, contract, legal hold, dispute, security, audit, suppression or provider requirement, SMSFlow applies the following standard periods:
- accounting, invoice, purchase-order and tax records: seven years;
- customer account and administrative records: five years after the last purchase, or longer where law requires;
- supplier records: seven years after the supply relationship ends;
- contracts: the agreement term plus the period reasonably required for prescription, disputes, legal holds and statutory obligations;
- contacts and prospect records: 24 months from the last meaningful interaction or unsuccessful engagement;
- consent and suppression evidence: five years;
- messages and delivery events: 12 months;
- media and message attachments: 90 days;
- conversations and inbox content: 12 months;
- templates: the life of the template plus 24 months;
- provider-operation history: 24 months;
- raw webhooks: 90 days;
- normalised events: 12 months;
- outbox and inbox records: 12 months;
- failures and dead letters: 90 days;
- standard security telemetry: 12 months;
- security-incident evidence: 24 months after incident closure;
- audit logs and privileged administrative actions: 24 months;
- backups and disaster-recovery copies: a rolling 90 days;
- test and harness evidence: 90 days; and
- test evidence supporting a release, incident or audit finding: 24 months.
Payment records held by SMSFlow are limited to invoices, balances, transaction references, status, and masked card or payment metadata supplied by an approved payment provider. SMSFlow does not intend to store full payment-card credentials. SMSFlow is implementing the approved periods across the Services through automated controls and documented operational procedures. Until a relevant automated control is available, the period is applied through an appropriate operational process.
13. Your rights
Subject to POPIA and other applicable law, a data subject may request confirmation of processing, access, correction, deletion or destruction, objection, restriction, withdrawal of consent, information about recipients, and review of an applicable automated decision. Rights may be limited by legal, contractual, security, evidentiary, or third-party rights.
Where SMSFlow processes Customer Data as operator, the relevant customer is generally responsible for responding. SMSFlow will refer the request to the customer and provide reasonable assistance. SMSFlow will respond directly for processing where it is the responsible party.
Requests may be sent to [email protected]. SMSFlow may verify identity and authority and will not disclose another person’s or tenant’s data. PAIA requests must use Form 2 available from the Information Regulator at https://inforegulator.org.za/paia-forms/. SMSFlow will ordinarily decide a properly submitted PAIA request within 30 calendar days, subject to any extension permitted by law. The complete procedure and complaint route appear in the PAIA Manual.
14. Direct marketing by SMSFlow
SMSFlow may send its own direct marketing only where permitted by POPIA and other applicable law. Recipients may opt out without charge using the mechanism in the communication or by contacting SMSFlow. An opt-out will be applied according to its scope and will not prevent necessary service, security, legal, or transactional communications.
SMSFlow customers conduct their own campaigns as responsible parties and must comply with the Messaging Policy and their own notices.
15. Cookies and website analytics
SMSFlow websites may use necessary cookies and, where approved, analytics or marketing technologies. The final website must provide a cookie notice that identifies each non-essential technology, purpose, provider, duration, and choice mechanism. Non-essential tracking must not be described or activated inconsistently with applicable consent requirements.
Available cookie controls and the applicable cookie notice identify non-essential technologies enabled on the relevant website, their purpose, provider and duration. SMSFlow reviews website tags periodically and updates the notice where the deployed technologies change.
16. Data deletion, account closure, and WABA offboarding
Requests may be made through the published privacy or support channel. SMSFlow will verify authority, identify affected systems and subprocessors, provide a tracking reference, and explain legally permitted exceptions.
Account closure or WABA offboarding may include disabling sends and automation, disconnecting webhooks, removing or revoking SMSFlow-held access and secret references where supported, and preserving customer ownership and portability where provider rules allow.
Deletion may exclude data subject to backup expiry, legal hold, security and audit requirements, billing and reconciliation, dispute evidence, or suppression protection. Provider-side deletion is governed by the provider; SMSFlow cannot promise deletion from systems it does not control.
The website should publish a short stable deletion-instructions page at https://smsflow.co.za/data-deletion/ that directs requesters to this section and the approved request channel. It must not create a second privacy policy.
17. Children and regulated use
SMSFlow does not knowingly offer accounts to children. Customers using the Services in education, healthcare, financial services, gambling, alcohol, or another regulated context must first ensure that the use is lawful, permitted by the channel provider, appropriately age/country gated, and contractually approved by SMSFlow.
18. Changes to this Notice
SMSFlow may update this Notice to reflect legal, provider, security, product, or business changes. The published Notice will show its version and effective date. Material changes will be communicated where required or reasonably appropriate. The approved new Notice replaces prior SMSFlow privacy wording; it does not operate as a competing notice.
19. Complaints
Please first contact [email protected] so SMSFlow can investigate. You may also lodge a complaint with the Information Regulator of South Africa using PAIA or POPIA Form 5, as applicable.
Information Regulator contact details: Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191; telephone 010 023 5200; general enquiries at [email protected]; PAIA complaints at [email protected]; and POPIA complaints at [email protected]. Current forms and complaint procedures are available at https://inforegulator.org.za/.
